How to block attempted admin logins with WordFence

Updated on August 26, 2025

WordFence has the ability to automatically block IP addresses that attempt to sign into the WordPress website with a common administrator account name.

Common admin usernames

Tip: review Common administrator usernames attempted by hackers for a list of common admin usernames you can enter into WordFence.

Instructions

  1. Log into your WordPress site as an administrator

  2. From the side menu, go to WordFence > Firewall

  3. Click All Firewall Options

  4. Locate the text box with the label Immediately block the IP of users who try to sign in as these usernames

    If you entered usernames in the past, you will see them listed under the box.

  5. Type a username into the text box and hit enter

    Once you hit enter, the username will be listed under the box.

  6. Click SAVE CHANGES at the top of the page

See also

License

Licensed under CC BY 4.0

You are free to share and adapt this content for any purpose as long as you give appropriate credit in a reasonable manner.

No affiliate links

We do not participate in affiliate marketing, and we are not paid to mention products.

Leave a Reply

Your email address will not be published. Required fields are marked *